CDOE | Certified Defense Operations Expert
Become the analyst who can find what others miss.
CDOE turns alerts, logs, memory, network traffic, and attacker behavior into one connected investigation. Learn to hunt threats, contain incidents, engineer stronger detections, and brief leadership with confidence.
Operational skill—not memorized vocabulary.
You will learn the complete defensive workflow: recognize meaningful activity, validate evidence, reconstruct an intrusion, contain the threat, improve detection coverage, and communicate what happened in a professional incident report.
Investigate the Signal
Turn noisy alerts into a defensible conclusion by correlating endpoint, identity, DNS, firewall, and application telemetry.
Reconstruct the Attack
Build a reliable timeline from initial access through persistence, lateral movement, command-and-control, and impact.
Lead the Response
Contain and eradicate safely, preserve evidence, document decisions, and give leadership a clear path to recovery.
Six disciplines. One connected mission.
The labs are designed as realistic investigations, not isolated button-clicking exercises. Each discipline strengthens the next until you can handle a complete incident independently.
SIEM & Log Analysis
Query and correlate Windows, Linux, firewall, DNS, and application logs in Splunk and Elastic-style workflows.
Threat Hunting
Form hypotheses, inspect process trees, uncover living-off-the-land activity, and detect command-and-control beacons.
Incident Response
Work ransomware, business email compromise, and advanced intrusion scenarios from triage through recovery.
Digital Forensics
Analyze Windows disks and memory, recover artifacts, examine the registry, and build evidence-backed timelines.
Malware Analysis
Move from safe static inspection to controlled behavioral analysis and extract indicators defenders can act on.
Detection Engineering
Write, test, tune, and explain Sigma and YARA detections while measuring false positives and coverage gaps.
Every investigation makes the next one harder—and you stronger.
You begin with guided evidence analysis, then progress into increasingly independent incidents. By the final practical, you are responsible for the decisions, the evidence, and the report.
Guided Analysis
Learn the tools and reasoning process with structured objectives, curated telemetry, and instructor direction.
Incident Scenarios
Investigate realistic ransomware, account compromise, insider-threat, and command-and-control activity.
Readiness Runs
Work under uncertainty with more noise, fewer hints, competing priorities, and formal reporting requirements.
Final Capstone
Own a complete enterprise investigation and prove that you can turn evidence into decisive action.
Built to feel like an operations floor—not a quiz.
Isolated Investigation Environments
Work inside dedicated scenarios designed for safe analysis, repeatable practice, and hands-on experimentation.
Live Telemetry & Realistic Noise
Separate normal business behavior from malicious activity across multiple evidence sources and timelines.
Clean Scenario Resets
Restart an exercise, test a different theory, and repeat difficult workflows until the process becomes instinctive.
Progressive Independence
Guidance deliberately decreases as your analytical judgment, documentation, and response confidence increase.
The Final Defensive Capstone
Enter an isolated enterprise environment with a real compromise to investigate. You will use SIEM, endpoint, network, and forensic evidence to determine what happened—and what the organization must do next.
Train for the investigation you cannot afford to mishandle.
Build the technical judgment, evidence discipline, and communication skills expected from a capable SOC and incident-response professional.
Start CDOE — $400Includes one complimentary exam retake. Additional retakes are $150.